Skip to content
RESEARCH INDEX BREACHROAD / INTELLIGENCE NOTE

OSCP+ 2026 exam guide: format, points and strategy

OSCP+ is a hands-on pentest and Active Directory exam. Learn its current format, scoring, evidence rules, report requirements and 70-point strategy.

PUBLIC RESEARCH
AUTHOR
/ CEO of Breachroad · OSCP · PNPT
PUBLISHED
27 June 2026
READING TIME
11 min read
TOPIC
Careers and Certifications
OSCP+ 2026 exam guide: format, points and strategy

The OSCP+ exam in 2026 remains fully practical: a candidate receives a private VPN containing vulnerable systems, gains access, escalates privilege and documents the complete path. Under OffSec’s current guide, the technical portion lasts 23 hours and 45 minutes, followed by another 24 hours for report submission.

There are no formal prerequisites. In practice, candidates need fluent enumeration, exploitation of applications and services, Linux and Windows privilege escalation, tunnelling and Active Directory tradecraft.

Current OSCP+ structure and points

The exam contains:

  • three standalone machines worth 20 points each;
  • 10 points for initial access and 10 for privilege escalation on each;
  • one three-host Active Directory set worth 40 points;
  • supplied credentials for the AD set, simulating an assumed-breach scenario.

The pass mark is 70 out of 100. OffSec lists example combinations: complete AD plus three local.txt flags; complete AD plus two local flags and one administrative flag; partial AD combined with standalone progress; or all three standalone systems plus the first AD objective.

The scoring model matters: completion of everything is unnecessary, but deliberate score-building is essential. Two hours without new evidence should trigger a target change or a return to enumeration.

Treat Active Directory as one chain

The AD set is not three unrelated boxes. The initial credential leads through domain enumeration, trust relationships, permissions, services and lateral movement. Practise this end-to-end flow:

  1. identify the principal, groups and policies;
  2. enumerate shares, SPNs, ACLs and sessions;
  3. obtain or abuse credentials;
  4. move through WinRM, WMI, SMB or another exposed service;
  5. escalate to the objective’s required privilege;
  6. enumerate again after every new access level.

Do not run an entire toolbox without a hypothesis. Record which identity reaches which host and where every secret originated.

Flags and evidence determine points

The contents of local.txt and proof.txt must be submitted in the control panel before the technical period ends and shown in the report. OffSec requires candidates to read a flag from its original location in an interactive shell with cat or type. Another method, including a web shell, can result in zero points for that target.

Include the flag and host-identifying information in the screenshot. Immediately after access, preserve commands, output, IP address, user and time. Never postpone evidence collection until the end.

Time management

Spend the first 45–60 minutes on broad enumeration, then select the path with the strongest signals. Put a limit on one hypothesis and take breaks; OffSec explicitly expects candidates to eat, rest and sleep.

A useful rhythm is:

  • enumerate and take notes in parallel;
  • checkpoint every 60–90 minutes;
  • update the score table after every flag;
  • capture and describe evidence immediately;
  • re-enumerate after each privilege change;
  • reserve time to verify evidence before closing the VPN.

Machines can be reverted, but the operation removes your changes. The current limit is 24 reverts and can be reset once during the exam.

Tools, exploits and judgement

Read the current exam guide before starting because rules can change. Build a workflow around tools whose output you understand. Automated scanning does not replace manual validation, and public exploits need review and often modification.

When an exploit is modified, the report must include the changed code, original URL, highlighted edits and an explanation. The same discipline applies to a professional penetration test.

A readiness threshold

A candidate is ready when they can complete a full machine within a timebox without a walkthrough, reproduce every step from their own notes and produce a clear report. A high box count means little if each path required hints.

Run at least one 24-hour simulation before booking and use a structured 12-week OSCP+ study plan. Passing is the result of a repeatable method, not one lucky exploit.


The final two weeks

Run at least one full rehearsal under exam-like conditions: limited time, contemporaneous notes, breaks and final report export. Classify technical gaps as well as time lost to enumeration without a hypothesis, disordered notes and missing evidence.

Prepare a stable workstation, updates, a rule-compliant backup connection and pre-start checklist. Do not publish or use material that violates exam rules. Format, points, permitted tools and proctoring can change; the current Exam Guide is authoritative on exam day, not numbers remembered from an article.

Sources: OffSec OSCP+ Exam Guide, PEN-200 Syllabus, OffSec proctored exams.

SHARE / COPY